Total CVEs

140,151

Critical Severity

3,698

High Severity

13,312

Last 7 Days

1,761
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1,561 - 1,580 of 36,556 CVEs
CVE-2026-54665 MEDIUM - 5.3

Apache NiFi 0.0.1 through 2.9.0 support building qualified URLs from one of several HTTP request headers that provide an alternative to the standard Host header without validating the values provided. Apache NiFi 1.6.0 introduced a configurable application property to restrict values provided in the...

Vendor: Apache Software Foundation
Product: Apache NiFi
Published: Jun 22, 2026
Source: NVD
CVE-2026-44914 HIGH - 7.2

Apache NiFi 1.12.0 through 2.9.0 are missing authorization when replacing Process Groups that include extension components with specific Required Permissions based on the Restricted annotation. The Restricted annotation indicates additional privileges required, but framework authorization did not ch...

Vendor: Apache Software Foundation
Product: Apache NiFi
Published: Jun 22, 2026
Source: NVD
CVE-2026-44913 HIGH - 7.2

Improper escaping of database table names in the CaptureChangeMySQL Processor included with Apache NiFi 1.2.0 through 2.9.0 allows for injecting SQL commands using crafted naming. Manual quoted boundaries added in Apache NiFi 1.8.0 narrowed the scope of potential injection options, but did not cover...

Vendor: Apache Software Foundation
Product: Apache NiFi
Published: Jun 22, 2026
Source: NVD
CVE-2026-44911 MEDIUM - 6.3

Authorization handling for component configuration verification requests in Apache NiFi 1.15.0 through 2.9.0 allows clients with read access to submit proposed configuration properties. The proposed properties override current configuration, enabling users with read access to invoke predefined verif...

Vendor: Apache Software Foundation
Product: Apache NiFi
Published: Jun 22, 2026
Source: NVD
CVE-2025-66336 HIGH - 8.1

Apache Doris MCP Server contains a SQL injection vulnerability in a metadata query path. A user-controlled database name is directly interpolated into a SQL query, and the query is executed without passing the caller's authorization context. This may allow an authenticated attacker, or an anony...

Vendor: Apache Software Foundation
Product: Apache Doris MCP Server
Published: Jun 22, 2026
Source: NVD
CVE-2025-62198 MEDIUM - 5.4

An authenticated user can perform XSS. This issue affects Apache Atlas versions 2.4.0 and earlier. Users are recommended to upgrade to version 2.5.0, which fixes the issue.

Vendor: Apache Software Foundation
Product: Apache Atlas
Published: Jun 22, 2026
Source: NVD
CVE-2026-8157 HIGH - 8.8

The Vitepos WordPress plugin before 3.4.2 does not properly restrict the roles that can be assigned when creating new users via one of its REST API endpoints, allowing authenticated users with a custom Vitepos WordPress plugin before 3.4.2 role to escalate privileges to administrator.

Published: Jun 22, 2026
Source: NVD
CVE-2026-7859 MEDIUM - 5.3

The Motors WordPress plugin before 1.4.110 does not have proper authorisation and CSRF checks on one of its AJAX actions, allowing unauthenticated attackers to modify arbitrary post metadata, such as the gallery, featured image and, on WooCommerce sites, product prices.

Published: Jun 22, 2026
Source: NVD
CVE-2026-6858 HIGH - 7.1

The Transbank Webpay WordPress plugin before 1.14.0 does not sanitize and escape logs to be displayed, allowing unauthenticated users to perform Stored XSS attacks against logged in administrator

Published: Jun 22, 2026
Source: NVD
CVE-2026-4259 HIGH - 7.1

The ultimate-woocommerce-auction-pro WordPress plugin through 2.4.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

Published: Jun 22, 2026
Source: NVD
CVE-2026-4110 MEDIUM - 6.1

The ultimate-woocommerce-auction-pro WordPress plugin through 2.4.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

Published: Jun 22, 2026
Source: NVD
CVE-2026-10530 MEDIUM - 5.3

The Pie Register WordPress plugin before 3.8.4.10 does not use sufficiently random values when generating its account verification tokens, allowing unauthenticated attackers to predict a valid token and activate an account without access to the associated email inbox.

Vendor: Unknown
Product: Pie Register
Published: Jun 22, 2026
Source: NVD

An insecure process execution vulnerability exists in the pc-printer-updater.exe component of the PaperCut Print Deploy Client for Windows. The application, which typically operates with high-level system privileges, attempts to perform an internal validation check by invoking a secondary system uti...

Published: Jun 22, 2026
Source: NVD

A permissive list of allowed inputs in ASUS Armoury Crate allows a local administrator to perform arbitrary memory read/write operations or cause a system crash (BSOD) by bypassing the validation mechanism.Refer to the ' Security Update for Armoury Crate Appย ' section on the ASUS Security ...

Published: Jun 22, 2026
Source: NVD

A vulnerability has been identified in centraldogma-server-auth-shiro versions prior to 0.84.0, where the SearchFirstActiveDirectoryRealm substitutes the login username into an LDAP search filter without neutralizing LDAP filter metacharacters, allowing an unauthenticated attacker to manipulate the ...

Vendor: LY Corporation
Product: Central Dogma
Published: Jun 22, 2026
Source: NVD

A vulnerability has been identified in centraldogma-server versions prior to 0.84.0, where enabling ZooKeeper replication without setting replication.secret causes the server to silently fall back to a hard-coded, publicly known secret. This default credential authenticates the embedded ZooKeeper en...

Vendor: LY Corporation
Product: Central Dogma
Published: Jun 22, 2026
Source: NVD

A vulnerability has been identified in centraldogma-server-mirror-git versions prior to 0.84.0, where the Git mirror SSH client does not verify remote host keys for git+ssh:// connections, allowing an on-path attacker to perform man-in-the-middle attacks and compromise mirrored repositories.

Vendor: LY Corporation
Product: Central Dogma
Published: Jun 22, 2026
Source: NVD

A security flaw has been discovered in Browserbase up to 20260526. This impacts an unknown function of the component Autobrowse Trace Artifact Handler. The manipulation results in incorrect default permissions. The attack requires a local approach. The exploit has been released to the public and may...

Product: Browserbase
Published: Jun 22, 2026
Source: NVD
CVE-2026-12822 MEDIUM - 5.3

A vulnerability was identified in langflow-ai langflow up to 1.9.3. This affects an unknown function of the component Bundle URL Loader. The manipulation leads to code injection. The attack needs to be performed locally. The vendor was contacted early about this disclosure but did not respond in any...

Vendor: langflow-ai
Product: langflow
Published: Jun 22, 2026
Source: NVD
CVE-2026-12821 MEDIUM - 6.3

A vulnerability was determined in FlowiseAI Flowise up to 3.1.2. The impacted element is an unknown function of the file packages/components/nodes/documentloaders/S3/S3.ts of the component S3 Document Loader. Executing a manipulation can lead to path traversal. It is possible to launch the attack re...

Vendor: FlowiseAI
Product: Flowise
Published: Jun 22, 2026
Source: NVD